mm2-analytics-roblox-tracker
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to clone a repository from
https://8015238355.github.io. Cloning from a GitHub Pages subdomain rather than a standard repository is highly irregular and represents an unverifiable source for executable code, which is then run viasetup.sh. - [PRIVILEGE_ESCALATION]: The troubleshooting section encourages the use of
sudo ./setup.sh --install. This directs the user to grant administrative privileges to a shell script downloaded from an untrusted and suspicious remote source. - [METADATA_POISONING]: While the skill's frontmatter and README claim it is for "analytics and inventory management," the installation instructions reveal the project directory is named
murder-mystery-dupe-roblox. The term "dupe" is a well-known red flag in the Roblox community, typically associated with item duplication scams and malicious account-stealing scripts. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted gameplay data, creating a potential injection surface.
- Ingestion points: Reads gameplay data from
./data/gameplay_history.jsonand./data/raw_gameplay.json(SKILL.md). - Boundary markers: None identified in the instruction set to separate untrusted data from system prompts.
- Capability inventory: Capability to execute shell commands (
setup.sh) and perform network operations viaAIIntegrationusing external API keys. - Sanitization: No evidence of input validation or escaping for the ingested JSON data.
- [COMMAND_EXECUTION]: The skill uses
chmod +x setup.shand./setup.shto execute arbitrary shell commands during the installation process.
Recommendations
- AI detected serious security threats
Audit Metadata